Sarcouncil Journal of Multidisciplinary
Sarcouncil Journal of Multidisciplinary
An Open access peer reviewed international Journal
Publication Frequency- Monthly
Publisher Name-SARC Publisher
ISSN Online- 2945-3445
Country of origin- PHILIPPINES
Frequency- 3.6
Language- English
Keywords
- Social sciences, Medical sciences, Engineering, Biology
Editors

Dr Hazim Abdul-Rahman
Associate Editor
Sarcouncil Journal of Applied Sciences

Entessar Al Jbawi
Associate Editor
Sarcouncil Journal of Multidisciplinary

Rishabh Rajesh Shanbhag
Associate Editor
Sarcouncil Journal of Engineering and Computer Sciences

Dr Md. Rezowan ur Rahman
Associate Editor
Sarcouncil Journal of Biomedical Sciences

Dr Ifeoma Christy
Associate Editor
Sarcouncil Journal of Entrepreneurship And Business Management
Governance, Risk, and Compliance (GRC) Engineering Approaches for IT and Cybersecurity Control Assurance: A Critical Review
Keywords: GRC Engineering, Cybersecurity Control Assurance, Risk-Based IT Auditing, NIST COBIT Integration, Cybersecurity Governance United States.
Abstract: In the United States (U.S.), where escalating cyber threats such as ransomware and supply chain attacks increasingly imperil national security and economic stability, Governance, Risk, and Compliance (GRC) engineering has emerged as a critical mechanism for Information Technology (IT) and cybersecurity control assurance. This critical literature review examines peer-reviewed academic studies, standards-informed research, and authoritative professional literature from 2020 to 2025, confined to U.S. regulatory contexts. Employing a critical review methodology, it inductively surfaces themes from recurring patterns, contrasts, and tensions across sources, viewed through lenses of functional integration, risk alignment, control effectiveness, auditability, and scalability in regulated environments. This involves thematic coding to derive patterns, evaluative comparison to assess strengths and weaknesses, and contradiction mapping to identify inconsistencies and gaps. The analysis reveals a dominant emphasis on hybridizing frameworks such as National Institute of Standards and Technology (NIST) and Control Objectives for Information and Related Technology (COBIT) to unify governance and risk functions, alongside risk-based control design and automation for monitoring and predictive analytics. While these approaches demonstrably bolster enterprise risk management and sectoral resilience particularly in finance and healthcare, they simultaneously expose persistent weaknesses. This can be in the form of limited adaptability, insufficient cultural integration, scalability constraints for smaller entities, and unresolved contradictions in AI adoption amid fragmented regulations like SOX, HIPAA, and CCPA. Empirical validation remains thin, and behavioral dimensions are largely overlooked. These findings carry significant implications for assurance quality, regulatory accountability, and institutional resilience. The review illuminates how current GRC engineering supports risk-based auditing yet falls short in addressing the full complexity of U.S. regulated environments, thereby clarifying both its contributions and its enduring limitations.
Author
- William Asare Yirenkyi
- Temple University - Fox School of Business Philadelphia PA.